# nestarc > Open-source NestJS reliability building blocks for multi-tenant SaaS backends. Canonical site: https://nestarc.dev/ Organization: https://nestarc.dev/about GitHub: https://github.com/nestarc npm: https://www.npmjs.com/org/nestarc ## Start here - https://nestarc.dev/getting-started - https://nestarc.dev/packages/ - https://nestarc.dev/guide/ - https://nestarc.dev/api/ - https://nestarc.dev/blog/ - https://nestarc.dev/faq ## @nestarc/tenancy 0.16.1 Confirm the installed package version and peer dependencies before applying an example. This guide describes tenancy 0.16.1 with Node.js ^22.13.0 || ^24.0.0, NestJS 10/11, and Prisma 6/7. - Agent usage guide: https://nestarc.dev/packages/tenancy/agent-guide - Installation and role/RLS prerequisites: https://nestarc.dev/packages/tenancy/installation - Authentication and identifier extraction: https://nestarc.dev/packages/tenancy/extractors - Public API and subpaths: https://nestarc.dev/api/tenancy/modules - Migration: https://nestarc.dev/packages/tenancy/migration - CLI check and JSON doctor: https://nestarc.dev/packages/tenancy/cli - Runnable source example: https://github.com/nestarc/nestjs-tenancy/tree/v0.16.1/examples/quickstart Headers and decoded JWT claims do not authorize tenant access. Authenticate before extraction, authorize membership, use a restricted non-owner database role, and apply RLS policies. Raw SQL requires explicit transaction-local context. Repository main can contain changes not yet published to npm; compare its version and release notes with the installed package. ## @nestarc/audit-log 0.7.0 Confirm the installed version with `npm ls @nestarc/audit-log`. These guides cover published 0.7.0 with Node.js ^22.13.0 || ^24.0.0, NestJS 10/11/12.0.1+, Prisma 5/6/7, and PostgreSQL. Prisma 7 uses the generated client namespace and PostgreSQL adapter; existing Prisma 5/6 client construction can remain in place. - Run the pinned example and verify the first role change: https://nestarc.dev/packages/audit-log/quickstart - Adopt one manual business event or one tracked model: https://nestarc.dev/packages/audit-log/adoption - Agent usage guide: https://nestarc.dev/packages/audit-log/agent-guide - Shared configuration, schema, and module installation: https://nestarc.dev/packages/audit-log/installation - Automatic tracking boundaries: https://nestarc.dev/packages/audit-log/auto-tracking - Manual events and caller-owned transactions: https://nestarc.dev/packages/audit-log/manual-logging - Authorized history queries: https://nestarc.dev/packages/audit-log/query-api - Upgrade to 0.7.0: https://nestarc.dev/packages/audit-log/migration - Published public API: https://nestarc.dev/api/audit-log/ - Version-pinned release source: https://github.com/nestarc/nestjs-audit-log/blob/v0.7.0/CHANGELOG.md Start with one role change and verify actor, authorized tenant, before/after values, masking, and rollback. A manual user.role.changed event records application-supplied values in metadata.role; an automatic User.updated record uses changes.role. Manual adoption needs only the module and table: await log(input, tx) inside an ordinary Prisma transaction and let errors escape. Automatic adoption uses trackedModels: ['User'] and withAuditTransaction(); caught atomic audit/policy errors still prevent commit. defineAuditConfig() builds module, optional extension, schema, and partition options without database work or Nest registration. actorRequired defaults to false; enabling it requires a non-blank string ID for system actors too. Use actorExtractionStage: 'interceptor' after authentication Guards; middleware remains the default. Actor extraction and tenant audit context do not authenticate, authorize, or scope business queries. Use trusted tenant context and tenant predicates in business queries. Atomic tracked createMany, updateMany, createManyAndReturn, and updateManyAndReturn are rejected before mutation; returning-bulk rejection is a breaking change in 0.7.0. Use sequential supported writes inside the helper. deleteMany has a per-record cap. Nested writes to tracked models are rejected even through untracked parents. Base clients, raw SQL, database cascades, and intentional exclusions are not automatically audited. best-effort is non-atomic; returning bulk APIs produce no automatic rows. For soft-delete composition, choose a companion whose peer range includes 0.7.0 (soft-delete 0.7.4) and verify the exact runtime tuple; older 0.5.0/0.7.2 examples are historical. Follow the site's version-pinned Quick Start instructions: the 0.7.0 source artifact contains older 0.6.0 example pins and pre-publication wording. ## @nestarc/feature-flag 0.5.0 Confirm the installed package version first. These guides cover published feature-flag 0.5.0 with NestJS 10/11, Prisma 7, and Node.js ^20.19.0 || ^22.12.0 || >=24.0.0. The source package is now 0.6.0, pending npm publication; use a locally packed 0.6.0 tarball to verify its changes. - Agent usage guide and release limitations: https://nestarc.dev/packages/feature-flag/agent-guide - Installation through the first HTTP result: https://nestarc.dev/packages/feature-flag/installation - Evaluation and percentage precedence: https://nestarc.dev/packages/feature-flag/rollout - Attribute overrides and testing: https://nestarc.dev/packages/feature-flag/tenant-overrides - Cache consistency: https://nestarc.dev/packages/feature-flag/cache-adapters - Custom storage registration and version boundary: https://nestarc.dev/packages/feature-flag/custom-backends - Published public API and subpaths: https://nestarc.dev/api/feature-flag/modules In 0.5.0, prefer a stable explicit userId or tenantId for percentage rollouts. Explicit targetingKey and registry bucketBy have service-path limitations described in the agent guide. Direct repository and tenantContextProvider options are included in 0.6.0, pending npm publication. The global enabled field is a fallback after overrides and percentage evaluation; Redis invalidation is best-effort. Test consumer builds and real integration behavior rather than treating service stubs as rollout tests. ## @nestarc/webhook 0.13.1 Confirm the installed version and peer dependencies. Published webhook 0.13.1 supports NestJS 10/11 and Prisma 5/6/7; Prisma 7 requires a generated client and PostgreSQL adapter. The source package is now 0.13.2, pending npm publication; use a locally packed 0.13.2 tarball to verify its changes. Use the Node.js version intersection documented by the chosen NestJS and Prisma versions. - Agent usage guide and release limitations: https://nestarc.dev/packages/webhook/agent-guide - Install, register an endpoint, publish, and inspect delivery: https://nestarc.dev/packages/webhook/installation - Publishing and tenant scope: https://nestarc.dev/packages/webhook/sending-events - Recorded attempts, retry, and replay: https://nestarc.dev/packages/webhook/delivery-logs - Signature freshness, receiver deduplication, and key snapshots: https://nestarc.dev/packages/webhook/security - Published API reference: https://nestarc.dev/api/webhook/ - Korean introduction: https://nestarc.dev/ko/packages/webhook/ send() matches endpoints across all tenants; use sendToTenant() for tenant events. SKIP LOCKED coordinates claims but cannot prevent repeated HTTP requests. Receivers need persistent webhook-id deduplication as well as raw-body HMAC and timestamp checks. Keys are snapshotted at delivery creation. In 0.13.1, correlationId requires idempotencyKey, replay always gets five total attempts, and the host must block retries after payload purge. Source 0.13.2 fixes those limitations and coordinates retry with retention; it is pending npm publication. Do not rely on those fixes in an installed 0.13.1 package. ## @nestarc/outbox 0.3.0 Confirm the installed version with `npm ls @nestarc/outbox`. These guides cover published 0.3.0 with Node.js >=22, NestJS 10/11/12, Prisma 5/6/7, and PostgreSQL. Pair NestJS 12 with Schedule 12; Prisma 7's PostgreSQL adapter needs pg even when wakeups are disabled. - Agent usage guide and release limitations: https://nestarc.dev/packages/outbox/agent-guide - Install SQL, configure providers, and enable shutdown hooks: https://nestarc.dev/packages/outbox/installation - Delivery guarantees, leases, and retry scheduling: https://nestarc.dev/packages/outbox/how-it-works - Publisher adapters and stable message identities: https://nestarc.dev/packages/outbox/transports - Published API reference: https://nestarc.dev/api/outbox/ - Korean introduction: https://nestarc.dev/ko/packages/outbox/ - Version-pinned README: https://github.com/nestarc/outbox/blob/v0.3.0/README.md - Version-pinned consumer fixtures: https://github.com/nestarc/outbox/tree/v0.3.0/test/packed-examples Apply the bundled SQL before starting the app and keep periodic polling enabled. In 0.3.0, notifications alone do not ensure backlog, future retry, or missed-notification recovery; listPage also loses sub-millisecond timestamp precision and must not be used as an exhaustive export. Enable Nest shutdown hooks for signal-driven cleanup; the poller waits up to 30 seconds. Preserve event IDs and metadata through brokers and deduplicate side effects. SENT is an acknowledgement, not downstream completion or FIFO. Repository main may contain fixes not yet published to npm. ## Notes for automated clients - Package compatibility and limitations are documented on each package page. - Technical articles include reviewed dates and version scopes. - Generated API references describe the current documented releases. - This file is a convenience index, not a ranking or citation signal.